Live data from Hacker News

GitHub under ongoing DDoS attack

status.github.com

161–170 of 352 posts

Re: GitHub under ongoing DDoS attack

#161

Earlier quoted context omitted.

When did writing ddos protection tools become a crime? Was that shortly after it became illegal to try to stop someone from stabbing you?

Maybe I misinterpreted the "or desperate enough," I don't know, but quite a lot of people in this thread seem very trigger happy. // Fun fact: Depending on what jurisdiction you're under and how the tool is implemented writing a DDoS protection tool might actually be considered a crime.

Yeah you did misinterpret his comment. Also, you can be "desperate" for help so I don't understand what you meant.

What jurisdiction or tool-implementation would consider DDoS prevention a crime? We're talking about mitigating a flood of traffic here.

Re: GitHub under ongoing DDoS attack

#162
Perhaps, if a country is shown to launch these kind of attacks[1], a second "great firewall" could be installed at peering points with that country, to filter out this kind of attack before it can reach the internet as a whole ...

[1] assuming, of course, this is the work of a government, and not simply some disenfranchised actors inside said government

Re: GitHub under ongoing DDoS attack

#163

Perhaps, if a country is shown to launch these kind of attacks[1], a second "great firewall" could be installed at peering points with that country, to filter out this kind of attack before it can reach the internet as a whole ... [1] assuming, of course, this is the work of a government, and not simply some disenfranchised actors inside said government

That wouldn't work here, from what I understand. This attack is only using hosts outside of China, not within.

Re: GitHub under ongoing DDoS attack

#164
post #83

Earlier quoted context omitted.

I spend about 6 months of the year in China. Yes, I am forced, as you say, to use the Chinese versions of everything, but, to be honest, it doesn't worry me. I use Baidu to put my teaching notes online for my students - it is as good as DropBox. Bing is allowed and works fine as a search engine, even if it blocks any results for "naughty" words. It becomes a bit of a game to see which double entendres it doesn't reco…

Are you really serious? Adblocking is trivial and does not require government censorship. And how does allowing access to Google let them rule the world?

I think you miss my point. As I see it, the Chinese government are basically blocking Google as a business decision. Take a look at Baidu. You will be amazed at the number of services they offer. On the roads in China you see a lot of Audis and Mercedes. These are mostly driven by Government officials. There are many avenues for Government officials to earn money. I don't know the size of companies like Baidu and Ali Baba, but I would warrant they are many times the size of Google and Amazon. Government officials want a piece of that action. If you really think this all about freedom of speech, you seem somewhat naïve to me. It's money, money, money.

Re: GitHub under ongoing DDoS attack

#167

Earlier quoted context omitted.

Maybe I misinterpreted the "or desperate enough," I don't know, but quite a lot of people in this thread seem very trigger happy. // Fun fact: Depending on what jurisdiction you're under and how the tool is implemented writing a DDoS protection tool might actually be considered a crime.

Yeah you did misinterpret his comment. Also, you can be "desperate" for help so I don't understand what you meant. What jurisdiction or tool-implementation would consider DDoS prevention a crime? We're talking about mitigating a flood of traffic here.

> Yeah you did misinterpret his comment.

Don't rub it in. I had a long night.

> What jurisdiction or tool-implementation would consider DDoS prevention a crime?

That depends on how the tool is implemented. Nobody cares what you use it for; what it does and what that (potentially) enables you to do is usually the deciding factor. I can't give you a concrete example because I'm not a judge and these kind of laws are way too vague anyway. We're obviously not talking about "traditional" methods here (hence the fun fact). Note that the problem is not you using a tool, it's you distributing a tool that can be used for ... well ... I don't know.

Re: GitHub under ongoing DDoS attack

#168
post #153

Hi, foreigner working in Chinese high tech company here. I wonder a bit, on which ground is this attack attributed to Chinese gov? It looks a bit unlikely to me. China has some cyber military but they are more likely to be pragmatic and choose wisely their targets. There's a bunch of script kiddies but they would choose also something else. However it seems possible that many servers hosted in China are not secured a…

This might be part of the attribution: https://news.ycombinator.com/item?id=9275381

Thanks, so if I understand well, every js gotten from baidu cdn from outside China has a malicious code attacking github. Weird. It could be some test gone wrong, but I still don't buy Chinese gov attacking purposely and openly github like that. It's like showing your one time secret weapon way too early and on some wrong target. Or maybe it's a way to make some big noise to the left while the real target is discretely owned on the right.

Re: GitHub under ongoing DDoS attack

#169
post #100

Earlier quoted context omitted.

China will be kicked from the internet at about the same time US and their NSA will be kicked. Which is quite unlikely. We don't kick out USA because NSA breaks into backbone routers, steal encryption codes from sim cards, and steal traffic from google search, Gmail and Facebook. China attacks github, and the reaction will be likely the same. At some point, it is going to make a economical sense to issue a treaty aga…

If the PRC were merely snooping, and not actively attacking, that equivalence would work. I was also under the impression that this is already in violation of treaty, the only saving grace for the PRC being that it hasn't been proven it's them.

I'm sorry, snooping?

Remotely transmitted malware.

Hardware caught in transit and infected by malware.

Firmware infected with malware at factories.

Bricked backbone routers, causing widespread outage during civil war.

Hacked phone companies.

Stuxnet, a computer worm designed to sabotage industrial centrifuges.

A $6 billion trade contract being manipulated in favor of Boeing.

A $1.3 billion contract trade contract being manipulated in favor of American defense contractor Raytheon.

Weakening products and standards that Internet users.

Should I continue? The list goes on and on and on as more leaks are reported on. Using that definition of snooping, we can just call PRC action snooping too.

Re: GitHub under ongoing DDoS attack

#170
I'd be interested to hear what this attack ends up costing GitHub in man power, bandwidth fees and so on. I wonder if any cost will be waived - I could see, for example, a large cost if they host DNS with AWS (although it sounds like they may host DNS at Akamai - I haven't checked as I'm writing on the go).
Post reply on HN